SOC2C

Is this your company? Buyers are checking Octopus Deploy here. Claim octopus.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Octopus Deploy logo

Octopus Deploy

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Octopus Deploy is SOC 2 Type II compliant. Octopus Deploy also holds ISO 27001, SOC 3, GDPR, CCPA, and PCI DSS.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the Octopus Deploy Trust Center! We are committed to providing you with world class standards of security & data privacy for all your deployment and continuous delivery needs. You can explore our [frequently asked questions](https://trust.octopus.com/faq), request access to comprehensive security documentation, and gain a clear understanding of how we [safeguard your data](https://trust.octopus.com/resources). Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives, just click the bell in the uppe

Compliance & infrastructure

Hosting
AWSAzure
Data handled
Credit card informationPersonal health informationCustomer Intellectual Property (configuration & scripts you upload to our service)Customer Personal Data (Name, email and billing address information)

Subprocessors

41
  • M
    Microsoft Azure · Cloud computing platform & LLM services (Copilot). Data subject's name, email, p
    USA, UK, EU, Australia, New Zealand, Canada
  • G
    Google · Document management, LLM Services (Gemini)
    USA
  • S
    SalesForce · Data subject's name, email, phone, company name and billing address.
    USA
  • Z
    Zendesk · Data subject name, email and any other Personal Data supplied.
    Australia, Germany, Ireland, Japan, USA
  • A
    Amazon Web Services · Data subject business contact information.
    USA, AU, UK
  • A
    Amplitude · Data analytics
    USA
  • A
    Avalara · Data subject's name, company, email and billing address.
    USA, EU, Switzerland, India, Brazil
  • C
    Chameleon Intelligence Inc. · Data subject name, and website interactions during support.
    USA
  • D
    Discourse · Data subject name, email any other Personal Data supplied
    USA
  • D
    Disqus · data subject name, email any other Personal Data supplied.
    India, Philippines, USA
  • D
    Docusign · Data subject's name, email, phone, company name and billing address.
    EU
  • G
    Google Workspace · Identity provider
    USA
Show all 41 subprocessors
  • G
    Gearset · Data subject's name, email, phone, company name and billing address.
    UK, USA
  • G
    GitHub · data subject name, email any other Personal Data supplied.
  • H
    Hotjar · Data analytics
    EU, UK, USA
  • L
    Lever by Employ · Only applicable to job applicants. Data subject's name, address, email, phone, e
    Australia, Canada, EU, UK, USA
  • M
    Marketo · Marketing automation platform. Data subject's name, email, phone, and company de
    UK, USA
  • O
    OneTrust · Cookie consent management. Visitor preference information.
    USA
  • O
    Outreach · Sales engagement platform. Data subject's name, email, phone, company name and b
    USA, Ireland, Belgium, Netherlands
  • P
    Planhat · Data subject name and business contact information.
    EU
  • S
    SendGrid · Data subject name and email.
    USA, EU, UK
  • S
    Shopify · Only relevant to users of our merchandise shop.Data subject’s name, email addres
    Australia, Canada, UK, USA
  • S
    Slack · Notifications from our websites to inform our employees of important interaction
    USA
  • S
    Snowflake · Cloud data storage platform, used for reporting and analytics. Data subject's na
    USA
  • S
    Sprout · Data subjects may supply username, profile picture, and first/last name, geograp
    USA
  • S
    Stitch Data · Octopus license information, CRM & sales data, order information and support tic
    EU, Switzerland, UK, USA
  • S
    Stripe · Only relevant to users purchasing our products online. Data subject's name, emai
    Australia, Canada, UK, USA
  • S
    SumoLogic · Data subject name and business contact email, IP addresses, browser user agent s
    Germany
  • U
    User Interviews · Data analytics. Data subject's name, email, phone, and company details.
    USA
  • W
    Workato · Data subject's name, company, email and billing address
    USA
  • X
    Xero · Only relevant for employees. Data Subject's name, email and company name.
    USA
  • Z
    Zapier · Workflow automation; may store metadata (names and email addresses)
    US
  • Z
    Zuora · data subject's name, company, email, credit card data, and billing address.
    USA
  • E
    Estuary · Real-time data replication, transformation, and synchronization across systems f
    Data is processed in either Google Cloud Platform (GCP) – us-central1 or Amazon Web Services (AWS) – eu-west-1, based on the user’s configuration.
  • D
    Dovetail Research · Data analytics
    Europe
  • G
    Greenhouse · Involves moving applicant data from its secure environment to third-party servic
    USA
  • O
    OpenAI · Engineering
    US
  • A
    Anthropic · Engineering
    US
  • G
    Gong · Sales
    US
  • O
    Okta (Auth0) · Identity provider
    US
  • L
    Linear · Collaboration
    US

Compliance leadership

The person who leads Octopus Deploy's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Octopus Deploy's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

New subprocessors, updates to existingApr 2026

We are writing to notify our subscribers of the following changes to our subprocessor list: Updated Microsoft & Google entries Added subprocessors for the purpose of generative AI services, general use: - Open AI - Anthropic Added for the purposes of customer experience: - Gong Added for the purpose of employee & customer experience, task tracking: - Linear Added for the purpose of authentication: - Auth0

New SOC2 Type II & ISO Report Available for Octopus & Codefresh customersApr 2026

We are pleased to share that our latest SOC 2 Type II report is now available for download. This report is scoped to include both Octopus Deploy and Octopus Cloud, as well as the Codefresh products, making it useful for all our customers when checking our security posture against this standard. The audit period for this report is from February 1, 2025, to January 31, 2026, and we plan to commence our next SOC2 audit in January 2027. ISO Certification: Our current ISO 27001 attestation is updated and covers our core infrastructure and product suites. You can request access to both attestations in our Resources section Happy deployments!!

2025 Pen Test Report AvailableMar 2026

Our 2025 Pen Test Report is now available. If you already have access to the Trust Center, you can download the report without signing an additional NDA. If you haven't completed an NDA, you will be asked to fill one out before requesting access to the report.

Update to Octopus Deploy's SubprocessorsAug 2025

In your Data Processing Agreement (DPA) with Octopus Deploy, we commit to notifying you before any new third-party sub-processor starts processing applicable data. We’re sending this message because we’re planning to appoint a new third-party sub-processor. No action is required from you. The new third-party sub-processor is Amplitude. Amplitude Session Replay provides analytics on how trial users interact with the product to help improve onboarding. This new third-party sub-processor has been verified to ensure they meet our security and privacy standards and will meet our data processing terms. No customer-owned production data will be provided to this sub-processor. If you’ve received this update by email, it is because you subscribed to our Trust Center. You can view the full list of Octopus Deploy’s subprocessors here: https://trust.octopus.com/subprocessors

Update to Octopus Deploy's SubprocessorsJul 2025

In your Data Processing Agreement (DPA) with Octopus Deploy, we commit to notifying you before any new third-party sub-processor starts processing applicable data. We’re sending this message because we’re planning to appoint a new third-party sub-processor. No action is required from you. The new third-party sub-processor is: Zapier. Zapier connects apps via automated workflows. This new third-party sub-processor has been verified to ensure they meet our security and privacy standards and will meet our data processing terms. No customer-owned data will be provided to these third parties until the sub-processor notification period has passed. If you’ve received this update by email, it is because you subscribed to our Trust Center. You can view the full list of Octopus Deploy’s subprocessors here: https://trust.octopus.com/subprocessors

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Octopus Deploy SOC 2 compliant?
Octopus Deploy is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Octopus Deploy ISO 27001 certified?
According to Octopus Deploy's public trust center, Octopus Deploy is ISO 27001 certified. On SOC2C this listing is Listed.
Is Octopus Deploy SOC 3 compliant?
According to Octopus Deploy's public trust center, Octopus Deploy is SOC 3 compliant. On SOC2C this listing is Listed.
Is Octopus Deploy GDPR compliant?
According to Octopus Deploy's public trust center, Octopus Deploy is GDPR compliant. On SOC2C this listing is Listed.
Is Octopus Deploy CCPA compliant?
According to Octopus Deploy's public trust center, Octopus Deploy is CCPA compliant. On SOC2C this listing is Listed.

Answers published by Octopus Deploy

Reproduced from Octopus Deploy's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What's the difference between Octopus Server and Octopus Cloud?
Octopus Server is hosted within your own environment (on premise), while Octopus Cloud is hosted in the cloud, in a region of your choosing. We designed both products to provide the same functionality. If you are using the Octopus Server product, you are taking responsibility for the security and integrity of the Octopus Server, which includes things like file storage, database protection, and the security of the underlying operating system. You can find information about secure configuration of the Octopus Server product on our website.
How long do you retain log data for?
We keep security logs for at least 12 months, this helps us perform the necessary forensic investigations in the unlikely event of a security incident. This is also done in order for us to meet ISO27001 & SOC II cybersecurity standards.
How does Octopus Cloud approach credential management?
Here at Octopus we pride ourselves on taking industry standards and current thinking in the cybersecurity space and applying them in our environment. We make use of MFA across the board, use password management tooling, do realtime access review as well as quarterly formal reviews, and we enforce strict password policies for all production environments. Our production environment is entirely segregated from any development and testing environments, and all of our highly skilled engineers have undergone specialist security training, and thorough background checks.
What is your incident response plan and process?
We have a fully documented Security Incident Response Plan (SIRP). Staff are trained in executing this plan and tabletop exercises are used to test the plan. We have a dedicated team of in-house specialists for security incident response. We used principles from FIRST and their PSIRT services framework to design our SIRP. https://www.first.org/standards/frameworks/psirts/psirt_services_framework_v1.1
What support do you offer to clients in the event of a security incident?
We are deeply invested in our customers success and will do what we can to provide you with any information we have with regards to security incidents related to your Octopus Deploy instance. We do not provide any specific security support services in the event of a security incident on your end. However, we are more than happy to assist with providing you with the maximum amount of detail we can provide you to assist with any forensic or analytical investigations you may need to perform. For Cloud customers this means we are able to provide application logging and security logs if required for your analysis. Please keep in mind that on-premise installations are self contained, and we do not keep any standing access to it, so our ability to provide forensic details will be limited, however we are available to advise you on how our product is intended to work, and share code where required to help you properly understand Octopus Server at runtime. If there is a security incident with our products we will inform and involve affected customers as soon as it is safe and practical to do so, while complying with any relevant cybersecurity incident notification reporting laws (e.g. GDPR notification timelines). We reach out to the administrators on file via our support teams.

Business & Industrial peers that completed SOC 2